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DETAILED ACTION 

Applicant's correspondence received on 7/14/08 is acknowledged. Claims 1-17, 19, 
20 are presented for examination. Claim 18 is cancelled. 



Claim Rejections - 35 USC § 102 

1 . The following is a quotation of the appropriate paragraphs of 35 U.S.C. 1 02 that 
form the basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a foreign country or in public 
use or on sale in this country, more than one year prior to the date of application for patent in the United 
States. 

Claims 15 and 16 are rejected under 35 U.S.C. 102(e) as being unpatentable 
by Johnson, Jr. (6,1 85,307 B1 ). 

Re claim 15, Johnson JR. discloses a method for securing a transaction 
comprising the steps of: providing a transaction device (tag unit 100), the transaction 
device including a random number generator (see e.g. col. 13, lines 44-46) , wherein 
the transaction device is associated with a transaction (See e.g. col. 10, lines 61-65); 
device identifier and a transaction device authentication tag, the transaction device 
identifier being different from the transaction device authentication tag generating a 
transaction device random number (See e.g. col. 10, lines 38-41); and transmitting the 
transaction device identifier, the transaction device authentication tag, and the 
transaction device random number (See e.g. col. 6, lines 33-43): and validating the 
transaction device based at least in part on both the transaction device identifier and the 
transaction device authentication tag, both having been received from the transaction 



Application/Control Number: 10/708,547 Page 3 

Art Unit: 3627 

device (See e.g. col. 24, lines 44-49), wherein the transaction device random number is 
used to lookup a previously stored decryption key for decrypting at least one of the 
transaction device identifier and the transaction device authentication tag, the 
transaction device random number having been received from the transaction device 
(See e.g. col. 11, lines 22-36; also col. 10, lines 50-65). 

Re claims 16, Johnson et al. disclose a method further including providing a 
transaction device reader, the reader including a reader random number generator; 
providing a reader random number generator for generating a reader random 
number; and validating at least one of the transaction device and the reader in 
accordance with at least one of the transaction device random number and the 
reader random number (See e.g. col. 10, line 65-67, col.11, lines 13, 11-14, 28-35). 

Claim Rejections - 35 USC § 103 

2. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in 
section 102 of this title, if the differences between the subject matter sought to be patented and the prior art 
are such that the subject matter as a whole would have been obvious at the time the invention was made to 
a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be 
negatived by the manner in which the invention was made. 

3. Claims 1-7, 9-12, 14, 19, and 20 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Seidman et al. (US 6671358 A1), as supported by the provisional 
(60/286309), in view of Johnson, Jr. (6,185,307 B1). 
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Re claims 1, Seidman et al. disclose a system for securing a Radio Frequency 
(RF) transaction comprising: a RADIO FREQUENCY IDENTIFICATION (RFID) 
transaction device operable to send an RF transmission (See e.g. col. 2, lines 36-42). 

Seidman et al. do not explicitly disclose a system comprising the transaction 
device including a database for storing a transaction device identifier and a 
transaction device authentication tag, wherein the transaction device identifier is 
different from the transaction device authentication tag; a transaction device random 
number generator for generating a transaction device random number , a transmitter 
operable to transmit the transaction device identifier, the transaction device 
authentication tag, and the transaction device random number; wherein the 
transaction device is validated based at least in part on both the transaction device 
identifier and the transaction device authentication tag, both having been received 
from the RFID transaction device; and wherein the transaction device random 
number is used to lookup a previously stored decryption key for decrypting at least 
one of the transaction device identifier and the transaction device authentication tag, 
the transaction device random number having been received from the RFID 
transaction device. 

However, Johnson JR. discloses a system comprising the transaction device 
including a database for storing a transaction device identifier and a transaction 
device authentication tag, wherein the transaction device identifier is different from 
the transaction device authentication tag {See e.g. col. 9, lines 1-4); a transaction 
device random number generator for generating a transaction device random number 
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(See e.g. col. 10, lines 38-41), a transmitter (transmitter 106) operable to transmit the 
transaction device identifier, the transaction device authentication tag, and the 
transaction device random number (See e.g. col. 6, lines 33-43); wherein the 
transaction device is validated based at least in part on both the transaction device 
identifier and the transaction device authentication tag, both having been received 
from the RFID transaction device (See e.g. col. 24, lines 44-49 - the code is 
transmitted to the host 300 to authenticate the tag. Each tag has a different 
authentication code, which is generated from the tag ID); and wherein the transaction 
device random number is used to lookup a previously stored decryption key for 
decrypting at least one of the transaction device identifier and the transaction device 
authentication tag, the transaction device random number having been received from 
the RFID transaction device (See e.g. col. 11, lines 22-36; also col. 10, lines 50-65). 

Therefore, it would have been obvious to a person of ordinary skill in the art, at 
the time of the invention, to modify Seidman et al., and include the steps comprising 
a transaction device random number generator for generating a transaction device 
random number , a transmitter operable to transmit the transaction device identifier, 
the transaction device authentication tag, and the transaction device random number; 
wherein the transaction device is validated based at least in part on both the 
transaction device identifier and the transaction device authentication tag, both 
having been received from the RFID transaction device; and wherein the transaction 
device random number is used to lookup a previously stored decryption key for 
decrypting at least one of the transaction device identifier and the transaction device 
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authentication tag, the transaction device random number having been received from 
the RFID transaction device, as taught by Johnson JR., in order to further secure 
transactions and prevent unauthorized interception of valuable information. 

Re claim 2, Seidman et al. disclose a system wherein further comprising: a 
RFID reader in communication with said transaction device; a merchant Point of Sale 
(POS) device in communication with said RFID reader (See e.g. col. 2, lines 43-47); 
and an account authorizing agent in communication with said merchant POS {See 
e.g. col. 17, lines 9-12). 

Re claims 3, 4 Seidman et al. disclose a system wherein said RFID reader 
comprises: a reader random number generator for producing a reader random 
number a system wherein said RFID reader further comprises: a processor in 
communication with said reader random number generator; and a system wherein a 
reader database for storing a RFID reader identifier (See e.g. col. 13, lines 17-25); 

Re claim 5, Seidman et al. disclose a system wherein said transaction device 
random number generator is operable to provide said transaction device random 
number to said RFID reader, said reader operable to provide said transaction device 
random number to said POS, said POS configured to provide the transaction device 
random number to said account authorizing agent system (See e.g. col. 13, lines 17- 
25). 
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Re claims 6, Seidman et al., disclose system wherein said RFID reader is 
operable to provide said transaction device identifier to said merchant POS (See e.g. 
col. 22, lines 51-59). 

Re claims 7 and 12, it would have been a design choice, at the time of the 
invention, to have at least one of said transaction device identifier and said 
transaction device random number provided to said RFID reader in track 1 /track 2 
International Standards Setting Organization format, in order to synchronize the 
system. 

Re claim 9, Seidman et al. do not explicitly disclose a system wherein said 
authorizing agent system is configured to validate said transaction device identifier in 
accordance with said transaction device random number (See e.g. col. 18, lines 42- 
51). 

However, Johnson JR. discloses a system wherein said authorizing agent 
system is configured to validate said transaction device identifier in accordance with 
said transaction device random number (See e.g. col. 11, lines 22-35). 

Therefore, it would have been obvious to a person of ordinary skill in the art, at 
the time of the invention, to modify Seidman et al., and include the steps wherein said 
authorizing agent system is configured to validate said transaction device identifier in 
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accordance with said transaction device random number, as taught by Johnson JR., 
in order to authenticate the device. 

Re claim 10, Seidman et al. disclose a system wherein said RFID reader 
random number generator is operable to provide said reader random number to said 
POS, said POS configured to provide at least one of said transaction device random 
number, transaction device identifier, and reader RFID reader random number to said 
account authorizing agent system (See e.g. col. 22, lines 48-59, col. 17, lines 9-12). 

Re claims 11 and 14, Seidman et al. disclose a system wherein said RFID 
reader is operable to provide at least one of said transaction device random number, 
transaction device identifier, and reader RFID reader random number to said 
merchant POS; a system wherein said authorizing agent system is configured to 
validate at least one of said transaction device and said RFID reader, in accordance 
with said at least one of said transaction device random number, transaction device 
identifier, and reader RFID reader random number transaction device random 
number (See e.g. col. 17, lines 9-42). 

Re claims 19 and 20, Seidman et al., do not explicitly disclose a method 
wherein the transaction device random number is converted to a validating code and 
then used to validate the transaction device; a new transaction device random 
number is generated for each transaction. 
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However, Johnson JR. discloses a method wherein the transaction device 
random number is converted to a validating code and then used to validate the 
transaction device (see e.g. col. 11, lines 33-35-67); a new transaction device 
random number is generated for each transaction (see e.g. col. 13, lines 65-67). 

Therefore, it would have been obvious to a person of ordinary skill in the art, at 
the time of the invention to modify Seidman et al., and include a method wherein the 
transaction device random number is converted to a validating code and then used to 
validate the transaction device; a new transaction device random number is 
generated for each transaction, as taught by Johnson JR., in order to alter the 
authentication process in such a way that only authorized devices can communicate 
with each other. 

4. Claims 8 and 13 are rejected under 35 U.S.C. 103(a) as being unpatentable 
over Seidman et al. (US 6671358 A1), as supported by the provisional (60/286309), in 
view of Johnson, Jr. (6,1 85,307 B1 ), in further view of Official Notice. 

Re claims 8 and 13, Seidman et al., in view of Johnson JR. do not explicitly 
disclose a system wherein at least one of said transaction device identifier and said 
transaction device random number is provided to said RFID reader in POS pre- 
defined format. 

However the Examiner takes Official Notice that it is well known in the art that 
a recognizable format should be provided to a receiving system in a network. 
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Therefore, it would have been obvious to a person of ordinary skill in the art, at 
the time of the invention to include a transaction device identifier and wherein said 
transaction device random number is provided to said RFID reader in POS pre- 
defined format, in order to synchronize the system. 

5. Claim 17 is rejected under 35 U.S.C. 103(a) as being unpatentable over 
Johnson, Jr. (6,185,307 B1), in view of Seidman et al. (US 6671358 A1), as supported 
by the provisional (60/286309), in further view of Weller etal. (2002/01 1919 A1). 

Re claim 17, Johnson Jr. discloses a method for securing a transaction 
comprising the steps of: providing a transaction device (tag unit 100), the transaction 
device including a random number generator (see e.g. col. 13, lines 44-46) , wherein 
the transaction device is associated with a transaction (See e.g. col. 10, lines 61-65); 
device identifier and a transaction device authentication tag, the transaction device 
identifier being different from the transaction device authentication tag generating a 
transaction device random number (See e.g. col. 10, lines 38-41); and transmitting, from 
the transaction device, the transaction device identifier, the transaction device 
authentication tag, and the transaction device random number to the transaction device 
reader; transmitting, from the transaction device reader, the transaction device identifier, 
the transaction device authentication tag, the transaction device random number, and 
the transaction device authentication tag to an account issuer associated with the 
transaction device (host 300) (See e.g. col. 10, lines 41-44); wherein the transaction 
device random number is used to decrypt at least one of the transaction device identifier 
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and the transaction device authentication tag, the transaction device random number 
having been received from the transaction device {See e.g. col. 18, lines 13-31). 

Johnson JR. does not explicitly disclose validating, at the account issuer, the 
transaction device (credit/debit card) based at least in part on both the transaction 
device identifier (credit/debit card number) and the transaction device authentication tag 
(code 245), both having been received from the transaction device. 

However, Seidman et al. disclose validating, at the account issuer, the 
transaction device (credit/debit card) based at least in part on both the transaction 
device identifier (credit/debit card number) and the transaction device authentication tag 
(code 245), both having been received from the transaction device (See e.g. col. 18, 
lines 13-31). 

Therefore, it would have been obvious to a person of ordinary skill in the art, at 
the time of the invention to include the steps of validating, at the account issuer, the 
transaction device based at least in part on both the transaction device identifier and 
the transaction device authentication tag, both having been received from the 
transaction device, as taught by Seidman et al., in order to verify the validity of the 
transaction device. 

Johnson JR., in view of Siedman et al. do not explicitly disclose validating, at 
the account issuer, the transaction device reader based at least in part on the 
transaction device reader authentication tag, wherein the transaction device random 
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number is used to decrypt at least one of the transaction device reader authentication 
tag. 

However, Weller et al. disclose validating, at the account issuer, the 
transaction device reader based at least in part on the transaction device reader 
authentication tag, wherein the transaction device random number is used to decrypt 
at least one of the transaction device reader authentication tag (see e.g. paragraph 
0099). 

Therefore, it would have been obvious to a person of ordinary skill in the art, at 
the time of the invention to include the steps of validating, at the account issuer, the 
transaction device reader based at least in part on the transaction device reader 
authentication tag, wherein the transaction device random number is used to decrypt 
at least one of the transaction device reader authentication tag, as taught by Weller 
et al., in order to prevent unauthorized access to the system by ensuring 
communication only with valid device readers. 

Response to Arguments 

6. Applicant's arguments with respect to the previous claims have been considered, 
but are moot in view of the new grounds of rejection. 
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Conclusion 

7. Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Luna Champagne whose telephone number is (571) 
272-7177. The examiner can normally be reached on Monday - Friday 8:30 - 5:00. 

If attempts to reach the examiner by telephone are unsuccessful, the 
examiner's supervisor, Florian Zeender can be reached on (571) 272-6790. The fax 
phone number for the organization where this application or proceeding is assigned 
is 571-273-8300. 

Information regarding the status of an application may be obtained from 
the Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR 
only. For more information about the PAIR system, see http://pair-direct.uspto.gov. 
Should you have questions on access to the Private PAIR system, contact the 
Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like 
assistance from a USPTO Customer Service Representative or access to the 
automated information system, call 800-786-9199 (IN USA OR CANADA) or 571- 
272-1000. 

Luna Champagne 

Examiner 

Art Unit 3627 

September 23, 2008 
IF. Ryan Zeender/ 

Supervisory Patent Examiner, Art Unit 3627 



